Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2023:1611-1 Important: Curl Memory Issues and Security Updates

suse
Calendar Grey May 24, 2023
Dist Suse Esm H88
Updates for SUSE containers release critical security fixes that tackle significant vulnerabilities, such as buffer overflows and additional concerns.
The container suse/sles/15.5/virt-handler was updated

Summary

Advisory ID: SUSE-SU-2023:2111-1 Released: Fri May 5 14:34:00 2023 Summary: Security update for ncurses Type: security Severity: moderate Advisory ID: SUSE-SU-2023:2224-1 Released: Wed May 17 09:53:54 2023 Summary: Security update for curl Type: security Severity: important

References

References : 1210434 1211230 1211231 1211232 1211233 CVE-2023-28319 CVE-2023-28320

CVE-2023-28321 CVE-2023-28322 CVE-2023-29491

1210434,CVE-2023-29491

This update for ncurses fixes the following issues:

- CVE-2023-29491: Fixed memory corruption issues when processing malformed terminfo data (bsc#1210434).

1211230,1211231,1211232,1211233,CVE-2023-28319,CVE-2023-28320,CVE-2023-28321,CVE-2023-28322

This update for curl adds the following feature:

Update to version 8.0.1 (jsc#PED-2580)

- CVE-2023-28319: use-after-free in SSH sha256 fingerprint check (bsc#1211230).

- CVE-2023-28320: siglongjmp race condition (bsc#1211231).

- CVE-2023-28321: IDN wildcard matching (bsc#1211232).

- CVE-2023-28322: POST-after-PUT confusion (bsc#1211233).

Severity
important
Lowest
Low
Medium
High
Critical

Container Advisory ID : SUSE-CU-2023:1611-1
Container Tags : suse/sles/15.5/virt-handler:0.58.0 , suse/sles/15.5/virt-handler:0.58.0-150500.6.3 , suse/sles/15.5/virt-handler:0.58.0.18.333
Container Release : 18.333
Severity : important
Type : security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here